plugin

Userplus Vulnerabilities

10 known security issues reported for the Userplus WordPress plugin. Most recent disclosed Nov 20, 2024.

2 critical 1 high 2 medium

Running Userplus on your site? Check whether your installed version is affected.

Scan your site free

User registration &amp; user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)

unknown

[en] Incorrect Privilege Assignment vulnerability in Userplus UserPlus allows Privilege Escalation.This issue affects UserPlus: from n/a through 2.0.

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Nov 20, 2024

CVE-2024-52442 on NVD →

UserPlus <= 2.0 - Privilege Escalation

critical

The User registration & user profile – UserPlus plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to gain administrator privileges.

CVSS:
9.8
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Nov 18, 2024

CVE-2024-52442 on NVD →

User registration &amp; user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)

unknown

[en] The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' p...

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Oct 10, 2024

CVE-2024-9518 on NVD →

User registration &amp; user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)

unknown

[en] The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or...

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Oct 10, 2024

CVE-2024-9520 on NVD →

User registration &amp; user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)

unknown

[en] The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level permissions or above, to update the registration...

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Oct 10, 2024

CVE-2024-9519 on NVD →

UserPlus <= 2.0 - Unauthenticated Privilege Escalation

critical

The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' functions. This makes it possible for unauthenticated attackers to specify their user role by supplying the 'role' parame...

CVSS:
9.8
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Oct 9, 2024

CVE-2024-9518 on NVD →

UserPlus <= 2.0 - Authenticated (Editor+) Registration Form Update to Privilege Escalation

high

The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. This makes it possible for authenticated attackers, with editor-level permissions or above, to update the registration form...

CVSS:
7.2
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Oct 9, 2024

CVE-2024-9519 on NVD →

UserPlus <= 2.0 - Missing Authorization via Multiple Functions

medium

The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to add, modify, or dele...

CVSS:
6.3
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Oct 9, 2024

CVE-2024-9520 on NVD →

User registration &amp; user profile – UserPlus [userplus] <= 2.0 (unfixed + closed)

unknown

[en] The User registration & user profile WordPress plugin through 2.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged-in admin add Stored XSS payloads via a CSRF attack.

Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Jan 16, 2024

CVE-2023-0824 on NVD →

UserPlus <= 2.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

medium

The UserPlus plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the 'save' function. This makes it possible for unauthenticated attackers to modify plugin options, including injecting malicious JavaScript into the plugin options, via a forged reques...

CVSS:
6.1
Affected:
up to 2.0
Fix:
No patched version reported
Disclosed:
Apr 12, 2023

CVE-2023-0824 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database